How to Send Sensitive Documents by Email Safely: A Checklist
How to send sensitive documents by email safely: expiring links instead of attachments, passwords by a separate channel, redaction that works, and a checklist.
A signed contract, a passport scan, a payroll file, a client's bank statement: at some point every small business has to send one, and the reflex is to attach it and press send. That attachment then sits in your Sent folder, the recipient's inbox, every device they sync, and any account either of you loses control of. Here is a safer routine that takes an extra minute and does not require the recipient to install anything.
Quick answer
Do not attach the document; share an expiring link from a file-sharing tool that requires a login or a password, and send the password by a different channel such as a text message or phone call. Redact what the recipient does not need using a tool that removes the data rather than drawing over it. Check the recipient address character by character, then send. Delete the shared file when the job is done.
The safe-send routine
- Decide whether the document needs to be sent at all. Often a reference number, the last four digits, or a screenshot of one field is enough.
- Redact anything beyond what the recipient needs. Use a redaction feature that removes the underlying content (Adobe Acrobat's Redact tool, or export a flattened image of the page), never a black rectangle drawn over text, which can be removed.
- Upload the file to a sharing tool that supports expiry and access control. Set the link to expire in days, not months, and limit downloads if the tool allows.
- If the tool supports a link password, set one, and send it by a second channel. If the recipient must sign in with their own account to view, that is better still.
- Write the email with the link and a one-line description. Do not put the password, the account number, or the full document details in the body.
- Verify the recipient address. Autocomplete is the leading cause of documents going to the wrong person; read the full address before sending.
- After the recipient confirms receipt, revoke the link and delete the file from the sharing tool if it is no longer needed.
Why links beat attachments
- You can revoke a link. You cannot recall an attachment.
- A link leaves nothing in the mailbox for a future attacker to find.
- Access logs show whether and when the file was opened.
- Large files do not bounce; most mail servers reject attachments above about 20 to 25 MB.
When an attachment is unavoidable
- Encrypt the file itself. A zip with AES-256 (7-Zip, or the built-in tools on macOS) or a PDF with a strong owner and user password using AES-256.
- Send the password by phone or text, never in the same email or a follow-up email to the same address.
- Use a long random password from your password manager, not the client's surname.
- Delete the attachment from your Sent folder after delivery is confirmed, and ask the recipient to delete the email once they have saved the file.
Redaction that actually works
Highlighting text in black in a PDF viewer or a word processor hides it on screen but leaves it in the file, where anyone can select and copy it. Real redaction removes the content and, ideally, the metadata (author, revision history, tracked changes). The reliable methods are a dedicated redact tool, or converting the page to an image and back to PDF. For spreadsheets, copy only the needed columns into a new file rather than hiding columns; hidden columns are still there.
Receiving sensitive documents from clients
Clients will email you passport scans and bank statements unprompted. Give them a better option: a dedicated upload link on your website, or a shared folder you create per client. When a sensitive attachment does arrive, move it to your document system and delete the email. Keep the mailbox that receives client documents on your own domain, with two-factor authentication on; OquMail provides such mailboxes free on your domain, with IMAP so your desktop client can file attachments straight into your document system.
Common questions
Is a Google Drive or OneDrive link secure?
It can be, if you restrict access to specific people or require sign-in, and set expiry. An "anyone with the link" share with no expiry is barely better than an attachment.
What about sending my own ID documents to a client or a registry?
Same rules. Send a link with expiry where the recipient's process allows; where they insist on an attachment, encrypt it and send the password by phone. Add a visible watermark stating the purpose and date, which limits reuse of the scan.
Should we ban attachments entirely?
Not necessary. Ban attachments for a defined list of document types (identity, financial, medical, contracts before signature) and route those through links. Everything else can go as attachments as usual.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free